Privacy Policy
Effective date: June 8, 2026 · Last updated: June 8, 2026
1. Who we are
inSpring TalentOS (the “Platform”) is operated by inSpring LLC (“inSpring”, “we”, “us”, “our”). The Platform connects candidates, universities, training institutions, and employers to support education, credentialing, work authorization, and career placement.
If you have privacy questions, contact us at:
- Email: privacy@inspringcareers.com
- Mail: PO Box 810, 48 Waterfield Road, Winchester, MA 01890
2. Information we collect
We collect information in three ways: information you give us, information we collect automatically, and information we receive from third parties (your employer, school, or recruiter).
2.1 Account & profile
When you register or are added to the Platform we collect:
- Name, email address, phone / WhatsApp number, country of residence
- Country of birth (used to determine visa pathway)
- Role (candidate, advisor, recruiter, employer representative, etc.)
- Profile photo (optional)
2.2 Documents and credentials
To support credentialing, licensure, and visa filing, candidates upload or have uploaded on their behalf:
- Transcripts and degree records
- License and certification records
- English language test results (TOEFL, IELTS, etc.)
- Credential evaluation reports
- Passports and government-issued identification
- Reference letters
- Resume / CV
- Immigration and work authorization documents (I-20, EAD, OPT, H-1B, visa stamps, etc.)
- Professional experience credentials
- Employment verification documents
These documents may include sensitive data such as date of birth and government-issued identifiers. We treat them accordingly under applicable privacy laws.
2.3 Communications
Every email, WhatsApp message, and SMS sent through the Platform — in either direction — is logged to the candidate’s record so advisors and recruiters have a unified history. This includes:
- Message content
- Sender / recipient addresses
- Subject lines, message IDs, and reply chains
- Attachments
- Delivery and read status (where available)
2.4 Course progress and assessments
If you enroll in a course or questionnaire on the Platform:
- Course completion percentages, grades, certificates
- Questionnaire responses
- Timestamps for activity, logins, and submissions
2.5 Payments
Payments are processed by Stripe. We collect:
- Stripe customer ID and payment intent identifiers
- Purchase history (item, amount, status, timestamp)
- We do not store full credit card numbers — Stripe holds those.
2.6 Hiring and placement data
When an employer partner is matched to a candidate, we collect:
- Interview rounds, notes, and outcomes
- Offer terms (where shared with us)
- Pipeline stage, sub-stage, and stage history
2.7 Automatically-collected information
- Authentication events (login, logout, password reset)
- IP addresses (transient — used for rate limiting and abuse detection)
- Browser / device user agent (transient — used for compatibility checks)
- Cookies necessary for keeping you logged in (no advertising cookies)
We do not use third-party advertising trackers and we do not sell or share your information for cross-context behavioral advertising.
3. How we use your information
We process your information to:
- Provide and operate the Platform (account creation, scheduling, document review, messaging, course delivery, employer matching)
- Communicate with you about your case (advisors, recruiters, status updates)
- Process payments
- Support work authorization and visa filing
- Match candidates to employers and academic programs
- Comply with legal obligations
- Investigate abuse, debug errors, and improve the Platform
- Send transactional emails (password resets, notifications). We do not use your information for marketing without your separate consent.
4. Third parties that receive your information
We use a small number of vendors (“sub-processors”) to operate the Platform. Each receives only the information needed for the service:
| Sub-processor | Purpose | Data shared |
|---|---|---|
| Supabase | Primary infrastructure (database, auth, storage) | All Platform data |
| Vercel | Application hosting | Request metadata; no persistent data storage |
| Stripe | Payment processing | Name, email, payment details |
| Resend | Transactional and reply email | Sender / recipient, subject, body, attachments |
| Twilio | WhatsApp and SMS delivery | Recipient phone number, message body |
| Canvas LMS (Instructure) | Course enrollment and training-progress tracking | Name, email, course enrollment and progress data |
| Anthropic (Claude) | AI features (see Section 5) | Resume text, optional report prompts |
| Sentry | Error monitoring | Error stack traces, request paths |
We have written data-processing agreements (DPAs) in place with each sub-processor.
We may also share information with:
- Employer partners when you are placed in their pipeline, limited to what they need to make hiring decisions.
- Academic / school partners when you are enrolled in their program.
- Recruiter partners working on your placement.
- Law enforcement / regulators, where required by law and after a legal review.
We do not sell your information.
5. AI processing notice
Two features on the Platform send your data to Anthropic’s Claude API:
- Resume parsing. When you upload a resume during a questionnaire, the text is sent to Anthropic to extract structured fields (employer history, dates, certifications). Up to 30,000 characters of resume content are sent per parse. Before any data is sent, you must check an explicit consent box confirming you understand your resume text will be processed by Anthropic’s AI. Your consent choice and timestamp are recorded.
- AI custom reports (admin-only). Admins may write natural-language prompts that are sent to Anthropic to generate database queries. Prompts may reference candidate names; the schema is shared but candidate row data is not sent to Anthropic — only the resulting query is run on our side.
Anthropic’s API is configured for zero-retention processing — your data is not stored or used to train models.
Every call to Anthropic’s API is recorded in an internal audit log that captures: which feature was used, the data categories involved, input/output size, the user who triggered it, whether consent was given, and the timestamp.
You can ask us to remove your resume’s parsed output at any time by emailing privacy@inspringcareers.com.
6. International transfers
inSpring serves candidates from many countries while operating infrastructure that is primarily US-hosted. As a result, your information will be transferred to and stored in the United States. Where applicable transfer mechanisms (e.g., Standard Contractual Clauses for EU/UK users) apply, we rely on them.
7. Data retention
We keep your information only as long as we need it. Retention windows by category are described in our Data Retention Policy, which is part of this Privacy Policy by reference.
If you ask us to delete your account, we will delete or de-identify your information within 30 days, except where we are required to keep records for legal, tax, or anti-fraud purposes. Backups containing your information may persist for up to 90 days after deletion before they are overwritten.
8. Your rights
Depending on where you live, you may have the right to:
- Access the information we hold about you
- Correct information that is inaccurate
- Delete your information (“right to erasure”)
- Object to or restrict certain processing
- Receive a copy of your data in a portable format
- Withdraw consent for processing that relies on consent
- Lodge a complaint with your local data protection authority
To exercise any of these, email privacy@inspringcareers.com. We will respond within 30 days.
We will not retaliate against anyone for exercising their privacy rights.
9. Security
We protect your information with:
- Encryption in transit (TLS) and at rest
- Role-based access controls and row-level database security
- Authentication via Supabase Auth with bcrypt-hashed passwords
- Audit logging of administrative and AI-report queries
- External error monitoring so production failures are caught quickly
- A documented backup and restore procedure with point-in-time recovery
No system is perfectly secure. If we ever experience a breach affecting your information, we will notify you and the relevant regulators in accordance with applicable law.
10. Children’s privacy
The Platform is intended for users aged 18 and older. We do not knowingly collect information from anyone under 18. If you believe we have, contact us and we will delete it.
11. Changes to this policy
We may update this policy as the Platform evolves. Material changes will be communicated by email at least 14 days before they take effect. The effective date at the top of this page reflects the most recent change.
12. Consent acknowledgement
By creating an account on the Platform, or by continuing to use the Platform after the effective date above, you acknowledge that you have read this Privacy Policy and consent to the processing described. Specific operations that require additional explicit consent (e.g., AI resume parsing) will surface their own consent prompts.